// For flags

CVE-2019-6855

 

Severity Score

7.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.

Existe una vulnerabilidad de Autorización Incorrecta en EcoStruxure Control Expert (todas las versiones anteriores a la 14.1 Hot Fix), Unity Pro (todas las versiones), Modicon M340 (todas las versiones anteriores a la V3.20) , y Modicon M580 (todas las versiones anteriores a la V3.10), que podría causar un bypass del proceso de autenticación entre EcoStruxure Control Expert y los controladores M340 y M580

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-25 CVE Reserved
  • 2020-01-06 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-863: Incorrect Authorization
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep584040 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep584040 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep584040 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep584040
Search vendor "Schneider-electric" for product "Modicon M580 Bmep584040"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh584040 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh584040 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh584040 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh584040
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh584040"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep586040 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep586040 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep586040 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep586040
Search vendor "Schneider-electric" for product "Modicon M580 Bmep586040"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh586040 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh586040 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh586040 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh586040
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh586040"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep581020 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep581020 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep581020 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep581020
Search vendor "Schneider-electric" for product "Modicon M580 Bmep581020"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep582020 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep582020 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep582020 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep582020
Search vendor "Schneider-electric" for product "Modicon M580 Bmep582020"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep582040 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep582040 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep582040 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep582040
Search vendor "Schneider-electric" for product "Modicon M580 Bmep582040"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep583020 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep583020 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep583020 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep583020
Search vendor "Schneider-electric" for product "Modicon M580 Bmep583020"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep583040 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep583040 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep583040 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep583040
Search vendor "Schneider-electric" for product "Modicon M580 Bmep583040"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep584020 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep584020 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep584020 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep584020
Search vendor "Schneider-electric" for product "Modicon M580 Bmep584020"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep585040 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep585040 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep585040 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep585040
Search vendor "Schneider-electric" for product "Modicon M580 Bmep585040"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh582040 Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh582040 Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh582040 Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh582040
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh582040"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep584040s Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep584040s Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep584040s Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep584040s
Search vendor "Schneider-electric" for product "Modicon M580 Bmep584040s"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh584040s Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh584040s Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh584040s Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh584040s
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh584040s"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh586040s Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh586040s Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh586040s Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmeh586040s
Search vendor "Schneider-electric" for product "Modicon M580 Bmeh586040s"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep582040s Firmware
Search vendor "Schneider-electric" for product "Modicon M580 Bmep582040s Firmware"
< 3.10
Search vendor "Schneider-electric" for product "Modicon M580 Bmep582040s Firmware" and version " < 3.10"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M580 Bmep582040s
Search vendor "Schneider-electric" for product "Modicon M580 Bmep582040s"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp3420302 Firmware
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420302 Firmware"
< 3.20
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420302 Firmware" and version " < 3.20"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp3420302
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420302"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp342020 Firmware
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp342020 Firmware"
< 3.20
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp342020 Firmware" and version " < 3.20"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp342020
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp342020"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp342000 Firmware
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp342000 Firmware"
< 3.20
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp342000 Firmware" and version " < 3.20"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp342000
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp342000"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp341000 Firmware
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp341000 Firmware"
< 3.20
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp341000 Firmware" and version " < 3.20"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp341000
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp341000"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp3420102 Firmware
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420102 Firmware"
< 3.20
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420102 Firmware" and version " < 3.20"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp3420102
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420102"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp3420302 Firmware
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420302 Firmware"
< 3.20
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420302 Firmware" and version " < 3.20"
-
Affected
in Schneider-electric
Search vendor "Schneider-electric"
Modicon M340 Bmxp3420302
Search vendor "Schneider-electric" for product "Modicon M340 Bmxp3420302"
--
Safe
Schneider-electric
Search vendor "Schneider-electric"
Ecostruxure Control Expert
Search vendor "Schneider-electric" for product "Ecostruxure Control Expert"
< 14.1
Search vendor "Schneider-electric" for product "Ecostruxure Control Expert" and version " < 14.1"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Ecostruxure Control Expert
Search vendor "Schneider-electric" for product "Ecostruxure Control Expert"
14.1
Search vendor "Schneider-electric" for product "Ecostruxure Control Expert" and version "14.1"
-
Affected
Schneider-electric
Search vendor "Schneider-electric"
Unity Pro
Search vendor "Schneider-electric" for product "Unity Pro"
*-
Affected